Dark Web Monitoring
CEO personal email found in data breach (unrelated service)
Personal Gmail of CEO found in fitness app breach. No corporate credentials exposed but increases social engineering risk.
Client list excerpt found on file-sharing forum
Partial client list (47 names) found on underground forum. Appears to be from 2024 CRM export. Investigation ongoing to determine source.
Phishing domain acme-legal-login.com registered on Namecheap
Look-alike domain registered 3 days ago. DNS points to known phishing infrastructure. Takedown request submitted to registrar.
acmelegal.co.uk listed in target reconnaissance dump
Domain appeared in automated reconnaissance output posted to paste site. Includes subdomain enumeration and port scan results.
acmelegal.co.uk referenced in threat actor forum discussion
Domain mentioned in Russian-language forum by user "kr4ken_0x" discussing UK law firm targets. No specific attack plans identified yet.
Legacy VPN credentials on dark web marketplace
Old VPN credentials for user a.wilson found on Genesis Market successor. Credentials are for deprecated VPN that has been decommissioned.
Internal document metadata containing employee names found on paste site
PDF metadata from 3 documents leaked to Pastebin. Contains author names and internal file paths. Documents appear to be older case files.
Company email addresses found in marketing data broker database
7 corporate email addresses found in B2B data broker listing. No passwords, but increases targeted phishing risk.
Password for k.brown@acmelegal.co.uk found in stealer log
Credentials harvested by Raccoon Stealer from infected home device. Includes browser-saved passwords, cookies, and session tokens.
Credentials matching j.smith@acmelegal.co.uk found on breach forum
Credential leaked in third-party breach (LegalDocs Pro). Password hash (bcrypt) exposed. Account pre-dates MFA enforcement.
Fake LinkedIn profile impersonating HR director
Fraudulent LinkedIn profile using company name and HR director photo. Used to solicit CVs/personal data from job seekers.
Email s.jones@acmelegal.co.uk in combo list on Telegram channel
Credential found in aggregated combo list (2.3M records). Password appears to be plaintext. Source: Telegram paste group.